ActiveDEMAND <= 0.2.46 - Missing Authorization
medium
The ActiveDEMAND plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 0.2.46. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 0.2.46
- Fixed in:
- 0.2.47
- Disclosed:
- Apr 16, 2025
CVE-2025-39513 on NVD →
ActiveDEMAND [activedemand] <= 0.2.46 (unfixed)
unknown
[en] Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects ActiveDEMAND: from n/a through 0.2.46.
- Affected:
- up to 0.2.46
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2025
CVE-2025-39513 on NVD →
ActiveDEMAND [activedemand] < 0.2.44
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.
- Affected:
- up to 0.2.44
- Fixed in:
- 0.2.44
- Disclosed:
- Jun 3, 2024
CVE-2024-35638 on NVD →
ActiveDEMAND <= 0.2.43 - Cross-Site Request Forgery
medium
The ActiveDEMAND plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.43. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site adm...
- CVSS:
- 4.3
- Affected:
- up to 0.2.43
- Fixed in:
- 0.2.44
- Disclosed:
- May 30, 2024
CVE-2024-35638 on NVD →
ActiveDEMAND [activedemand] < 0.2.42
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.
- Affected:
- up to 0.2.42
- Fixed in:
- 0.2.42
- Disclosed:
- May 17, 2024
CVE-2024-32809 on NVD →
ActiveDEMAND <= 0.2.41 - Unauthenticated Arbitrary File Upload
critical
The ActiveDEMAND plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the api_save_post() function in all versions up to, and including, 0.2.41. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...
- CVSS:
- 10
- Affected:
- up to 0.2.41
- Fixed in:
- 0.2.42
- Disclosed:
- Apr 22, 2024
CVE-2024-32809 on NVD →
ActiveDEMAND [activedemand] < 0.2.28
unknown
[en] Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
- Affected:
- up to 0.2.28
- Fixed in:
- 0.2.28
- Disclosed:
- Aug 5, 2022
CVE-2022-36296 on NVD →
ActiveDEMAND <= 0.2.27 - Missing Authorization Checks
critical
The ActiveDEMAND plugin for WordPress is vulnerable to unauthenticated post updates and deletion due to missing authorization checks in the api_save_post and api_delete_post functions called via REST APIs in versions up to, and including 0.2.27. This makes it possible for unauthenticated attackers to modify posts.
- CVSS:
- 9.8
- Affected:
- up to 0.2.27
- Fixed in:
- 0.2.28
- Disclosed:
- Aug 2, 2022
CVE-2022-36296 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database